πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ WordPress sites getting hacked β€˜within seconds’ of TLS certificates being issued πŸ—“οΈ

Attackers pounce before site owners can activate the installation wizard

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-24823 β€Ό

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Colonial Pipeline 1 Year Later: What Has Yet to Change? πŸ•΄

The incident was a devastating attack, but it exposed gaps in cybersecurity postures that otherwise would have gone unnoticed.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Passwords: Do Actions Speak Louder Than Words? πŸ•΄

For most of us, passwords are the most visible security control we deal with on a regular basis, but we are not very good at it.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ World Password Day – the 1960s just called and gave you your passwords back ⚠

Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-19215 β€Ό

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19213 β€Ό

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19212 β€Ό

SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19217 β€Ό

SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28970 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28972 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-19216 β€Ό

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28973 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28005 β€Ό

An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server, leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. Versions prior to version 18, Hotfix 1 Build 18.0.3.461 March 2022, are prone to an additional unauthenticated file system access to C:\Windows\System32.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28971 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28969 β€Ό

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
⚠ You didn’t leave enough space between ROSE and AND, and AND and CROWN ⚠

What weird bug connects the words THEREFORE, AND, SECONDLY, WHY, BUT and BESIDES?

πŸ“– Read

via "Naked Security".
πŸ›  Adversary3 2.0 πŸ› 

Adversary3 is a tool to navigate the vast www.malvuln.com malware vulnerability dataset.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ AT&T Expands Access to Advanced Secure Edge and Remote Workforce Capabilities πŸ•΄

AT&T SASE with Cisco Meraki offers fully integrated network and security tools for convenient, high-performing, and protected access from anywhere

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-28545 β€Ό

FUDforum 3.1.1 is vulnerable to Stored XSS.

πŸ“– Read

via "National Vulnerability Database".